Skip to content

HIPAANIST 800-53 crosswalk

A control-by-control mapping between HIPAA Security Rule (45 CFR Part 164, Subpart C) and NIST SP 800-53 Rev. 5. 9 mappings.

HIPAANIST 800-53RelationshipNotes
§164.308(a)(1)
Security management process
RA-3
Risk assessment
EquivalentOfficial mapping
Risk assessment & management
§164.308(a)(6)
Security incident procedures
IR-4
Incident handling
EquivalentOfficial mapping
Incident response & breach notification
§164.308(a)(6)
Security incident procedures
IR-6
Incident reporting
PartialCurated
Incident response & breach notification
§164.312(a)(1)
Access control
AC-2
Account management
EquivalentOfficial mapping
Access control & identity
§164.312(b)
Audit controls
AU-2
Event logging
EquivalentOfficial mapping
Logging, monitoring & detection
§164.312(e)(1)
Transmission security
SC-8
Transmission confidentiality and integrity
EquivalentOfficial mapping
Cryptography & data protection
§164.312(e)(1)
Transmission security
SC-28
Protection of information at rest
EquivalentCurated
Cryptography & data protection
§164.404
Notification to individuals
IR-4
Incident handling
RelatedCurated
Incident response & breach notification
§164.404
Notification to individuals
IR-6
Incident reporting
EquivalentOfficial mapping
Incident response & breach notification

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.